hyperf

Fail

Audited by Socket on Mar 7, 2026

2 alerts found:

AnomalyObfuscated File
AnomalyLOW
references/zh-cn/eco/box.md

The fragment is a usage/documentation guide for the Hyperf Box tool. It highlights typical supply-chain risk patterns: remote binary downloads, token-based API access, and a reverse proxy capability that can affect multiple upstream services. While not malicious by itself, the described workflow relies on trust in binary integrity and token security. To reduce risk, implement: binary signing and integrity checks, explicit token least-privilege scopes and secure storage, clear guidance on secure handling of tokens, and explicit security controls for the reverse proxy (authentication, access controls, logging). Recommend validating binaries via checksums/signatures and adding explicit security notes in the docs before adoption in production.

Confidence: 72%Severity: 60%
Obfuscated FileHIGH
SKILL.md

The skill is benign and proportionate to its stated purpose as a Hyperf 3.1 development assistant. It provides scaffolding examples and references to documentation without requesting credentials, performing external installs, or sending data externally. No security risks identified beyond typical developer tooling assumptions.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 7, 2026, 07:52 AM
Package URL
pkg:socket/skills-sh/fanqingxuan%2Fawesome-skills%2Fhyperf%2F@bcbb1ae5707fbfb60282aa09ab26c64d75be5f5c